Skip to content
zMed
Launch in your Hospital

Privacy Policy

Last updated: August 2026

How we handle patient data

zMed is HIPAA-aligned and acts as a business associate under executed Business Associate Agreements (BAAs) with the hospitals we serve. We process patient health information strictly for the purposes of diagnosis, treatment, and disease prevention workflows defined in those agreements. No patient data is collected on this website.

Information you give us

When you fill in a form on this website — contacting us, booking a demo, downloading the brochure, or applying for a role — we collect what you enter: name, email, phone, organisation, role, country, city, message content, and (for job applications) your résumé. Brochure downloads are verified with a one-time code sent to the email address or phone number you provide. We use this information to respond to your enquiry, send you what you asked for, and follow up about zMed. The lawful basis is your consent, given when you submit the form.

Information collected automatically

When you visit our demo and brochure pages, we record the visit together with your IP address, the approximate location derived from it (city, region, country), device and browser type, preferred language, screen size, the page that referred you, and any campaign parameters in the link. We use this to understand interest in zMed, follow up on sales enquiries, and prevent abuse of our forms; the lawful basis is our legitimate interest in operating and marketing our business. This website also uses privacy-respecting, first-party analytics and Vercel Web Analytics (cookieless) to measure page performance.

Cookies and local storage

We set one functional cookie, zmed_lead, after you submit a form, so that we can connect your later visits and downloads to your enquiry; it holds the contact details you gave us and expires after one year. Our analytics store a random visitor identifier in your browser's local storage. You can clear both at any time through your browser settings, and the site works without them.

Who processes this data

We use a small number of service providers to run this website: Vercel (website hosting, USA), Google Workspace (email delivery), MSG91 (SMS delivery of one-time codes, India), and Discord (delivery of enquiry notifications to our sales team, USA). Each receives only what it needs for its function. Your information may therefore be processed outside your own country, including in India and the United States. We do not sell your data.

Retention

Enquiry and lead records are kept for up to 24 months after our last contact with you, then deleted. One-time verification codes expire within 10 minutes. Job applications are kept for the duration of the recruitment process unless you ask us to retain them longer.

Safeguards

We apply physical, electronic, and managerial safeguards to protect both patient and prospect data. Internally, we operate to internationally recognised information-security and medical-device quality management standards.

Your rights

You can request access to, correction of, or deletion of the data we hold about you, or withdraw your consent to further contact, at any time by writing to contact@zmed.tech. If you are in India, our grievance officer can be reached at the same address, and if your grievance is not resolved you may complain to the Data Protection Board of India. If you are in the European Union, you may lodge a complaint with your supervisory authority.

Contact

Questions about this policy? Email contact@zmed.tech.